CVE-2026-13190
Telerik UI for ASP.NET AJAX unsafe type instantiation from persisted state in the persistence utilities -> remote code execution
- Severity
- critical
- Affected product
- Telerik UI for ASP.NET AJAX
- Affected versions
- Telerik UI for ASP.NET AJAX ≥ 2011.2.712, < 2026.2.708
- Fixed in
- Telerik UI for ASP.NET AJAX 2026.2.708
- Added to NewScan
- 2026-09-07
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Telerik UI for ASP.NET AJAX from its response and reports this CVE when the detected version falls inside the affected range below.
The framework-level unsafe type resolution the two persistence CVEs above sit on top of, and the reason its lower bound (2011.2.712) differs from theirs. RadPersistenceManager / RadDockLayout, not RadAsyncUpload, so it is a separate chain from the 13181-13184 batch and has no public exploit. Version-match only: whether a given app uses cookie-based or file-based persistence storage is not observable from outside, so the row reports the vulnerable BUILD rather than asserting the configuration.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →